MAL-2026-13478
Dashboard / Malicious Package / MAL-2026-13478
MAL-2026-13478
Summary: Malicious code in @cats-cdf/authentication (npm)
Details: Source: amazon-inspector (404569337a1e5fc46fff2584e052d2f9f99c3cb8d04e5fb3b5c5d633c178e01c) The package's preinstall lifecycle script runs on npm install and collects the installer's local username (whoami), hostname, and public IP address (fetched via ifconfig.me), then transmits them as query-string parameters in an HTTP GET request to a hardcoded subdomain of oast.fun (kwphewvexhjbtfduscqybx6q7c862eh0g.oast.fun). oast.fun is an out-of-band interaction/callback service commonly used for reconnaissance and exfiltration in dependency-confusion attacks. The behavior fires automatically on default install with no relation to any documented package purpose.
References: https://www.npmjs.com/package/@cats-cdf/authentication/v/3.1.1, https://www.npmjs.com/package/@cats-cdf/authentication/v/2.17.1
Affected packages
Package
Name: @cats-cdf/authentication
Purl: pkg:npm/%40cats-cdf/authentication
Affected ranges
Type: N/A
Events:
